2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58121 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.... |
| CVE-2025-8084 | MEDIUM | 6.8 | 0.4% | Nov 18, 2025 | The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.... |
| CVE-2025-63892 | MEDIUM | 6.8 | 0.3% | Nov 18, 2025 | A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_c... |
| CVE-2025-63883 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client... |
| CVE-2025-59117 | MEDIUM | 4.8 | 0.2% | Nov 18, 2025 | Windu CMS is vulnerable to multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the page editing endpoint windu... |
| CVE-2025-59116 | MEDIUM | 5.3 | 0.2% | Nov 18, 2025 | Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow ... |
| CVE-2025-59115 | MEDIUM | 5.4 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Stored Cross-Site Scripting (XSS) in the logon page where input data has no proper validation... |
| CVE-2025-59114 | MEDIUM | 6.5 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft spec... |
| CVE-2025-59112 | MEDIUM | 6.5 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft specia... |
| CVE-2025-59111 | MEDIUM | 6.5 | 0.3% | Nov 18, 2025 | Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET reques... |
| CVE-2025-59110 | MEDIUM | 6.5 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechani... |
| CVE-2025-55179 | MEDIUM | 5.4 | 0.1% | Nov 18, 2025 | Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.2... |
| CVE-2025-13349 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown p... |
| CVE-2025-12545 | MEDIUM | 5.3 | 0.3% | Nov 18, 2025 | The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is... |
| CVE-2025-12376 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Request ... |
| CVE-2025-10158 | MEDIUM | 4.3 | 0.3% | Nov 18, 2025 | A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based bu... |
| CVE-2025-41350 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store... |
| CVE-2025-41349 | MEDIUM | 5.4 | 0.3% | Nov 18, 2025 | Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store... |
| CVE-2025-13343 | MEDIUM | 5.4 | 0.3% | Nov 18, 2025 | A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function o... |
| CVE-2025-11427 | MEDIUM | 5.8 | 0.4% | Nov 18, 2025 | The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forg... |
| CVE-2025-13196 | MEDIUM | 5.4 | 0.1% | Nov 18, 2025 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Str... |
| CVE-2025-13133 | MEDIUM | 6.6 | 0.2% | Nov 18, 2025 | The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, ... |
| CVE-2025-12691 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2025-12639 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | The wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions plugin for WordPress is vulnerable to authorizati... |
| CVE-2025-12481 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now